diff --git a/rules/traffic-id.rules b/rules/traffic-id.rules index 1a942db..5e262ed 100644 --- a/rules/traffic-id.rules +++ b/rules/traffic-id.rules @@ -52,5 +52,5 @@ alert tls any any -> any any (msg:"SURICATA TRAFFIC-ID: twitter"; tls_sni; conte alert tls any any -> any any (msg:"SURICATA TRAFFIC-ID: whatsapp"; tls_sni; content:"whatsapp.com"; isdataat:!1,relative; flow:to_server,established; flowbits: set,traffic/id/whatsapp; flowbits:set,traffic/label/im; flowbits:set,traffic/label/file-transfer; noalert; sid:300000029; rev:1;) alert tls any any -> any any (msg:"SURICATA TRAFFIC-ID: instagram"; tls_sni; content:"instagram.com"; isdataat:!1,relative; flow:to_server,established; flowbits: set,traffic/id/instagram; flowbits:set,traffic/label/social-network; noalert; sid:300000030; rev:1;) alert tls any any -> any any (msg:"SURICATA TRAFFIC-ID: instagram"; tls_sni; content:"cdninstagram.com"; isdataat:!1,relative; flow:to_server,established; flowbits: set,traffic/id/instagram; flowbits:set,traffic/label/social-network; noalert; sid:300000031; rev:1;) -alert http any any -> any any (msg:"SURICATA TRAFFIC-ID: Debian APT-GET"; content:"debian.org"; http_host; content:"Debian APT"; http_user_agent; flow:to_server,established; flowbits:set,traffic/id/debian-apt; flowbits:set,traffic/label/software-update; noalert; sid:300000032;) -alert http any any -> any any (msg:"SURICATA TRAFFIC-ID: Ubuntu APT-GET"; content:"ubuntu.com"; http_host; content:"Debian APT"; http_user_agent; flow:to_server,established; flowbits:set,traffic/id/ubuntu-apt; flowbits:set,traffic/label/software-update; noalert; sid:300000033;) +alert http any any -> any any (msg:"SURICATA TRAFFIC-ID: Debian APT-GET"; content:"debian.org"; http_host; content:"Debian APT"; http_user_agent; flow:to_server,established; flowbits:set,traffic/id/debian-apt; flowbits:set,traffic/label/software-update; noalert; sid:300000032; rev:1;) +alert http any any -> any any (msg:"SURICATA TRAFFIC-ID: Ubuntu APT-GET"; content:"ubuntu.com"; http_host; content:"Debian APT"; http_user_agent; flow:to_server,established; flowbits:set,traffic/id/ubuntu-apt; flowbits:set,traffic/label/software-update; noalert; sid:300000033; rev:1;) diff --git a/traffic-id.py b/traffic-id.py index 02e86c4..056253a 100755 --- a/traffic-id.py +++ b/traffic-id.py @@ -125,7 +125,7 @@ def print_rules(args, output, config): if not args.disable_noalert: options.append("noalert") - options += ["sid:%d" % (SID)] + options += ["sid:%d" % (SID), "rev:1"] print("alert %s any any -> any any (%s;)" % ( proto, "; ".join(options)), file=output) @@ -149,7 +149,7 @@ def generate_rules(args): if filename.endswith(".yaml"): path = os.path.join(dirpath, filename) with open(path) as fileobj: - config = yaml.load(fileobj) + config = yaml.load(fileobj, Loader=yaml.Loader) if "labels" in config: LABELS.update(config["labels"]) if "id-map" in config: